Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*", "matchCriteriaId": "2879B3D6-4E10-494B-B221-61CF4FA3B2D7", "versionEndIncluding": "2.9.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*", "matchCriteriaId": "957FC43C-7DBF-445F-952D-2C3AFC3DAF53", "versionEndExcluding": "2.10.50", "versionStartIncluding": "2.10.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*", "matchCriteriaId": "5B9C6A38-B9F3-4B83-872E-4A7FCF10A2CF", "versionEndExcluding": "2.11.58", "versionStartIncluding": "2.11.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*", "matchCriteriaId": "43352BBA-DDE8-4542-A8E1-10762B634972", "versionEndExcluding": "3.0.29", "versionStartIncluding": "3.0.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*", "matchCriteriaId": "E42BDC5D-3F5F-45E4-9135-0AA3E4DA94CE", "versionEndExcluding": "3.1.7", "versionStartIncluding": "3.1.0", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote unauthenticated attacker to execute an arbitrary script on the logged-in user's web browser."}, {"lang": "es", "value": "Vulnerabilidad de cross-site scripting en las versiones de la serie a-blog cms Ver.3.1.x anteriores a la Ver.3.1.7, versiones de la serie Ver.3.0.x anteriores a la Ver.3.0.29, versiones de la serie Ver.2.11.x anteriores a la Ver. .2.11.58, versiones de la serie Ver.2.10.x anteriores a la Ver.2.10.50 y Ver.2.9.0 y anteriores permiten a un atacante remoto no autenticado ejecutar un script arbitrario en el navegador web del usuario que ha iniciado sesi\u00f3n."}], "id": "CVE-2024-23181", "lastModified": "2024-11-21T08:57:08.347", "metrics": {"cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.1, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "version": "3.1"}, "exploitabilityScore": 2.8, "impactScore": 2.7, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2024-01-23T10:15:10.493", "references": [{"source": "vultures@jpcert.or.jp", "tags": ["Vendor Advisory"], "url": "https://developer.a-blogcms.jp/blog/news/JVN-34565930.html"}, {"source": "vultures@jpcert.or.jp", "tags": ["Third Party Advisory"], "url": "https://jvn.jp/en/jp/JVN34565930/"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "https://developer.a-blogcms.jp/blog/news/JVN-34565930.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory"], "url": "https://jvn.jp/en/jp/JVN34565930/"}], "sourceIdentifier": "vultures@jpcert.or.jp", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-79"}], "source": "nvd@nist.gov", "type": "Primary"}]}